712-50 Question 108
Single answerLeading through Education and Awareness and Guarding from MisinformationA global company is rolling out a major security awareness campaign after several employees acted on false internal messages about a new password reset process. The misinformation spread quickly through collaboration tools and regional chat groups, causing help desk overload and several unnecessary credential submissions to a spoofed site. The CISO wants a long-term approach that improves workforce resilience without creating message fatigue or reducing trust in legitimate communications. Which action should the CISO prioritize FIRST to most effectively lead through education and awareness while guarding against future misinformation?
- A
Launch mandatory annual training for all employees focused on phishing indicators and disciplinary consequences for policy violations
- B
Establish a trusted internal communications framework with verified channels, message authentication cues, and role-based awareness reinforced by just-in-time microlearning and reporting mechanisms
- C
Block all non-approved collaboration channels and require that security announcements be distributed only by the IT department
- D
Increase the frequency of simulated phishing exercises immediately and publicly rank business units based on failure rates
Show answer and explanation
Correct answer: B
Explanation
The strongest executive response is to build a trusted internal communications model that reduces ambiguity and helps employees reliably identify authentic organizational messages. In this scenario, the failure was systemic: employees lacked both a dependable validation method and an awareness model suited to rapid misinformation spread through modern collaboration platforms. A CISO leading through education and awareness should coordinate with corporate communications, HR, IT, and business leaders to define approved channels, standardize communication templates, add recognizable authenticity cues where possible, and ensure simple reporting and verification pathways. Training should then reinforce these controls through targeted, role-based content and brief, context-specific reminders rather than relying solely on annual awareness sessions.
This approach is consistent with established best practices from NIST guidance on awareness and training, which emphasizes role-based education and ongoing reinforcement rather than one-time events, and with broader security culture principles that favor timely reporting, trust, and behavioral support. It also aligns with social engineering defense practices that recommend easy verification paths, clear escalation routes, and repeated reinforcement of expected behaviors. A CCISO-level leader should prioritize governance, communication integrity, and culture over punitive or purely technical reactions when misinformation is the core risk driver.
- A. Incorrect.
This is not the best first action. Annual training alone is typically insufficient for combating fast-moving misinformation because it is infrequent, generic, and often forgotten. Emphasizing disciplinary consequences may also discourage reporting and reduce psychological safety. While phishing education is useful, the scenario calls for a long-term, trust-preserving approach that addresses both communication integrity and behavioral reinforcement.
- B. Correct.
This is the best answer. The root issue is not only user susceptibility but also the absence of a reliable way for employees to distinguish legitimate internal messages from false ones. A trusted communications framework addresses governance, authenticity, and usability by defining official channels, adding recognizable verification cues, and enabling employees to validate and report suspicious messages. Combining this with role-based awareness and just-in-time microlearning supports behavior change without overloading staff. This aligns with executive-level security leadership by integrating communication strategy, culture, and operational response.
- C. Incorrect.
This is a plausible but overly restrictive response. Restricting channels may reduce some attack surface, but it does not solve the broader problem of employee ability to evaluate information or maintain trust across a large enterprise. It may also harm operations and encourage shadow communication practices. Additionally, requiring only IT to distribute security announcements ignores the need for coordinated communications involving security, HR, corporate communications, and business leadership.
- D. Incorrect.
This is not the best first action. Simulations can be valuable as part of a mature awareness program, but increasing them immediately after a misinformation event without first improving trusted communication patterns can create fatigue and resentment. Public ranking based on failure rates can undermine culture, discourage reporting, and shift focus from learning to blame. Effective awareness programs generally emphasize measurable improvement, targeted coaching, and positive reinforcement rather than public shaming.